Re: bridged vlan interfaces

Jonathan Thibault <[email protected]> Tue, 20 Nov 2007 14:07:10 -0500
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Grant Taylor wrote:
> So if I understand you correctly, you can have as many VLAN interfaces 
> on your Linux system with as many of those as you want in the bridge 
> with out a problem.  The problem comes when you try to configure the 
> SRW2024 with the extra VLANs?
>   
Not exactly.  The problem comes when those vlans see the network trunk, 
which I have to configure in the SRW2024 to see happening.  Or merely 
replace the SRW2024 by a plain switch and connecting the 'in' interface 
right into the trunk.  The problem does happen when the SRW2024 is not 
involved at all.

> Ok, this makes me think that this is indeed an ARP related problem.  I 
> mis-took you to having meant that a client with current traffic that was 
> working would stop if you made the change.
>   
Like I said, I'm not 100% sure of that but almost, based on the fact 
that if I remove the troublesome vlan interface from the bridge, and 
then add it back on, the traffic keeps flowing, even allowing for the 
time it takes for the bridge to actually accept the new interface.  
(forgot the name of that parameter)
> I understand and can sympathize with the politics.
>
> The only thing I can offer is that I had an install years ago that did 
> not have the trunking quite right between a Dell PowerConnect (really a 
> Marvel) switch that would pass regular traffic but not DHCP requests. 
> It turned out to be a problem that traffic would get tagged by the 
> switch (I think) and the system would see the traffic on the raw 
> interface but work with it any way despite the fact that it was tagged. 
>   In short, raw traffic that is usable does not necessarily equate to 
> untagged traffic.
>
>   
Working logically here and assuming that this is the issue, it would 
mean that some of my customers cannot handle 'tagged' ARP replies.  What 
is it then that lets the same type of traffic be untagged properly when 
only one vlan is on the bridge, but not when more than one vlan is on 
the bridge.  At some point we also had three vlans (2, 4 and 5) on the 
customer network with customers in each vlan.  But only vlan2 went 
through the bridge, the other two went to more simple NAT type gateways 
so I don't think this is an issue with just having multiple vlans on a 
trunk.  Not to mention vlan1 being the management vlan on the trunk 
too.  Anything untagged on that trunk gets tossed to vlan1.

Hmmmmmmm....  Maybe I could monitor vlan1 for the missing ARP replies...

Jonathan
> Grant. . . .
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Microsoft
> Defy all challenges. Microsoft(R) Visual Studio 2005.
> http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
> _______________________________________________
> Ebtables-user mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/ebtables-user
>   


-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/